CVE-2007-4164
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
07/08/2007
Last modified:
09/04/2025
Description
CRLF injection vulnerability in the redirect feature in Sun Java System Web Server 6.1 and 7.0 before 20070802, when the redirect Server Application Function (SAF) uses the url-prefix parameter and escape is disabled, or an Error directive uses the url-prefix parameter in obj.conf, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks.
Impact
Base Score 2.0
7.50
Severity 2.0
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:sun:java_system_web_server:6.1:*:*:*:*:*:*:* | ||
cpe:2.3:a:sun:java_system_web_server:6.1:sp1:*:*:*:*:*:* | ||
cpe:2.3:a:sun:java_system_web_server:6.1:sp2:*:*:*:*:*:* | ||
cpe:2.3:a:sun:java_system_web_server:6.1:sp3:*:*:*:*:*:* | ||
cpe:2.3:a:sun:java_system_web_server:6.1:sp4:*:*:*:*:*:* | ||
cpe:2.3:a:sun:java_system_web_server:6.1:sp5:*:*:*:*:*:* | ||
cpe:2.3:a:sun:java_system_web_server:6.1:sp6:*:*:*:*:*:* | ||
cpe:2.3:a:sun:java_system_web_server:6.1:sp7:*:*:*:*:*:* | ||
cpe:2.3:a:sun:java_system_web_server:7.0:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://secunia.com/advisories/26326
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-103003-1
- http://www.securityfocus.com/bid/25190
- http://www.securitytracker.com/id?1018504=
- http://www.vupen.com/english/advisories/2007/2766
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35783
- http://secunia.com/advisories/26326
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-103003-1
- http://www.securityfocus.com/bid/25190
- http://www.securitytracker.com/id?1018504=
- http://www.vupen.com/english/advisories/2007/2766
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35783